Academy/VMware Avi Load Balancer 30.x Specialist (6V0-22.25)/Lab B3: Avi WAF Policy for a Public-Facing Web App
This lab targets VCF 9.0

Lab B3: Avi WAF Policy for a Public-Facing Web App

VCF 9.0Intermediatespecialist⏱ 75 min

Objectives

  • Deploy Avi WAF in front of a web app and tune rules for false positives.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Avi Load Balancer 30.x Specialist

Tasks

Task 1 Lab B3: Avi WAF Policy for a Public-Facing Web App

Deploy Avi WAF in front of a web app and tune rules for false positives.

Step 1

Enable WAF policy on an existing Avi VS using OWASP CRS 3.x profile.

Step 2

Run OWASP ZAP against the VS and observe WAF signatures hitting.

Step 3

Tune exceptions: whitelist benign CSRF-token patterns, disable noisy rule.

Step 4

Enable learning mode, collect 24h of traffic, promote learnings to policy.

Step 5

Validate in logs that attack traffic is blocked while legitimate requests pass.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

WAF policy in detection mode producing false positives
Fix: Start WAF in detection mode (log only) for 2-4 weeks to baseline legitimate traffic and identify false positives. Common false positives: REST API calls triggering SQL injection rules, file upload endpoints triggering file inclusion rules. Create exception rules for known-good traffic patterns before switching to enforcement mode.
WAF blocking legitimate application functionality
Fix: After enabling enforcement mode, monitor application functionality and WAF logs simultaneously. A WAF rule blocking a legitimate POST request may break form submissions. Use Avi WAF learning mode to automatically suggest exceptions based on observed traffic patterns.
Not configuring WAF for the specific application's attack surface
Fix: Default WAF rule sets (CRS 3.x) are generic. A public-facing web app needs different rules than an internal API. Customize: disable rules irrelevant to the app's technology stack (e.g., PHP rules for a Java app), tune thresholds for application-specific parameters.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

WAF design demonstrates application security architecture. VCDX panelists test whether you understand the detection → tuning → enforcement lifecycle and how you minimize false positives.

⚠ Known Pitfalls (from Community KB)

Enabling WAF enforcement without a detection-mode learning period — legitimate traffic gets blocked.
Using default WAF rules without customization — excessive false positives erode operational trust.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.